Welcome | Sign In
ECommerceTimes.com
CRM

Salespeople and Telecommuters and Customers, Oh My

Print Version
E-Mail Article
Reprints
Salespeople and Telecommuters and Customers, Oh My

Internal users, in general, present the biggest risk to a company's security, commented Paul Henry, vice president of technology evangelism at Secure Computing. "It's not just salespeople. ... In my opinion, [teleworkers] are more dangerous to security than salespeople. Companies have had years of experience in reining in sales reps and instilling safe computing practices in them."


"Never, ever put client data on a laptop -- and if you absolutely must, keep that laptop physically attached to your body," says Sharon Klein, a partner with Pepper Hamilton who counsels clients on privacy issues and and advises them on how to deal Increase Customer Sales with Email Marketing -- Free Trial from VerticalResponse with the loss of sensitive customer data.

"If [a lost] laptop is not encrypted, that triggers notification of security breach laws," she told CRM Buyer. "Then you have to go into a legal cycle of sending out letters [and] offering free credit-monitoring services."

Besides the cost to reputation, the bite out of a company's bottom line is usually five to six digits, she estimates.

Imagine then, her shock when one of her law firm's laptops went missing, and client data was compromised.

The culprit? A vendor that downloaded information from the firm and then went to another client location. Although the sales Download Free eBook - The Edge of Success: 9 Building Blocks to Double Your Sales rep left the laptop in a locked room, it was stolen.

Encryption, Encryption, Encryption

Incredibly, the vendor tried to argue with Klein about liability and whether the missing laptop trigged the notification laws.

"Since it was only password-protected, it triggered them," she said, although opposing counsel tried to argue otherwise. "The law is very clear on that."

There are two points to the story: One, if you encrypt data on a laptop, then you do not have to go through the painful act of notifying your customers that you were careless and irresponsible with their data -- even if a machine is lost. Not many firms seem to realize that, Klein said.

Two: Beware of sales reps, vendors and any other third parties that have any level of access to your data. They are the ones who represent the biggest security risk to your company.

Internal Threat

Salespeople represent the biggest potential security risk to small and medium sized businesses, a recent MessageLabs survey showed. This result makes sense, Mark Sunner, chief security analyst at MessageLabs, told CRM Buyer.

"Salespeople are usually within the age of 25 to 35 and are power Internet users," he noted. "They are multitaskers and don't put security at the front of their concerns."

It is easy enough for a sales rep -- especially one who's on the road -- to send instant messages or e-mail from an unsecured laptop or personal device. It is also easy to lose those devices while traveling. Encryption is rarely used because of the time it takes to boot up a system.

"No one wants to wait five or ten minutes for a laptop to come online when they are making a client presentation," Sunner said.

Internal users, in general, present the biggest risk to a company's security, commented Paul Henry, vice president of technology evangelism at Secure Computing.

"It's not just salespeople. Consider teleworkers, which actually, in my opinion, are more dangerous to security than salespeople," he told CRM Buyer. "Companies have had years of experience in reining in sales reps and instilling safe computing practices in them."

Teleworkers, by contrast, are relatively new to the corporate world.

"Most sales reps cannot install anything on a laptop without company approval," he said. "Someone who works from home can have all kinds of software on the desktop without the company's knowledge."

Only Just Begun

This is only the beginning of the problem, said Stan Quintana, executive director, AT&T (NYSE: T), who is responsible for AT&T's Managed Security Services.

"It will be become more prevalent as more wireless computing devices come onto market," he told CRM Buyer. "It will multiply the number of access points for workers to pick up infections and pass them along to a corporate network."

The biggest sleeper issue, though, he said, is the risk posed by customers accessing a company's Web site. Now, most consumers expect to be able to pay bills online or from a PDA (personal digital assistant). "Conceivably, a consumer can unwittingly affect a network that way."

In fact, this is already happening: SQL injections are a prevalent form of attack. Typically, a hacker attaches malware as part of a SSL (secure socket layer) transaction with, say, a bank. It is then injected into the company's back-end system where it extracts information from a database.

The Internet-facing infrastructure is wide open at many corporations, Quintana noted.

"This is one of the biggest weak links in many companies' security apparatus: a Web-facing e-commerce infrastructure that does not have any security filtering."

Even companies that do have such filtering should not rest easy. Virus writers have proven to be resourceful and adaptable. As e-commerce continues to become more consumer-friendly, hackers will continue to avail themselves of the same entry points.


Print Version E-Mail Article Reprints More by Erika Morphy


More by Erika Morphy

Windows 7 Flies Off the Shelves
November 06, 2009
Early sales figures on Windows 7 boxed software suggest a high level of consumer enthusiasm for the OS. Unit sales were a whopping 234 percent higher than Vista's out of the gate. The revenue haul was not as impressive, as Microsoft offered sharp discounts to spur presales. Also, sales of PCs with Windows 7 preinstalled have been lackluster -- but October is historically a weak month for PC sales.
Southwest Doesn't Fool Around
November 06, 2009
Either Southwest Airlines had better deals for my favorite route than its competitors or its superior Web site tools made it easier for me to ferret them out. Either way, kudos to Southwest. In the not-so-hot department were the airline's long list of what passengers weren't allowed to do and its very short list of what Southwest was obliged to do for them. Left me feeling a little chilly.
Commerce Search Puts Google Inside Retailers' Catalogs
November 05, 2009
Google has launched a new cloud-based search tool targeting enterprise-level e-commerce operations, just in time for the 2009 holiday selling season. Commerce Search provides a set of features designed to improve the relevance of results for consumers searching a retailer's own product catalog, while boosting cross-selling opportunities.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network